Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and including version 1.7.22 allows a remote attacker to access developer files stored in an AWS S3 bucket, by reading credentials stored in plain text within the mobile application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-25T10:40:53

Updated: 2024-08-04T02:44:10.787Z

Reserved: 2021-09-06T00:00:00

Link: CVE-2021-40527

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-25T11:15:07.720

Modified: 2021-10-28T22:18:12.820

Link: CVE-2021-40527

cve-icon Redhat

No data.